A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
We have discovered 952,430 live websites that are affected by CVE-2021-44790.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 952,430 live websites (34% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 43 versions ( 36% of all versions) |
| 289,602 websites | |
| 96,611 websites | |
| 57,706 websites | |
| 42,168 websites | |
| 39,465 websites | |
| 34,093 websites | |
| 33,146 websites | |
| 27,398 websites | |
| 26,946 websites | |
| 25,640 websites |
| .com | 361,095 websites |
| .de | 56,715 websites |
| .org | 43,009 websites |
| .net | 37,155 websites |
| .ru | 34,615 websites |
| .it | 30,863 websites |
| .nl | 24,330 websites |
| .cz | 22,335 websites |
| .pl | 18,745 websites |
| .jp | 18,572 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| *************.***.****.****.************.net | *** | ||
| *********.net | *** | ||
| ***.****.us | *,*** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** | ||
| ******************.com | *,*** | ||
| ****.*********.net | *,*** | ||
| *******.org | *,*** | ||
| ****.com | *,*** |
FAQ